CVE-2017-12149

Description

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
94.294

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 5.0.0Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 5.1.0Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 5.1.1Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 5.0.1Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 5.1.2Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 5.2.0Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 5.2.1Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 5.2.2Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234